CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2015-1888

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.2 before 2.0.2-ICN-FP007 and 2.0.3 before 2.0.3-ICN-FP003, as used in Content Manager, FileNet Content Manager, Content Foundation, Content Manager OnDemand, and other products, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 3 Oct 2015
    4.3
    Medium

    CVE-2015-5651

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Dotclear before 2.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Oct 2015
    10
    Critical

    CVE-2015-0987

    Last Modified: 2 Jun 2026

    Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC unlock request.

    Published: 3 Oct 2015
    4.3
    Medium

    CVE-2015-7314

    Last Modified: 12 Apr 2025

    The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check.

    Published: 3 Oct 2015
    5
    Medium

    CVE-2015-5650

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in AjaXplorer 2.0 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 3 Oct 2015
    2.1
    Low

    CVE-2015-0988

    Last Modified: 12 Apr 2025

    Omron CX-One CX-Programmer before 9.6 uses a reversible format for password storage in project source-code files, which makes it easier for local users to obtain sensitive information by reading a file.

    Published: 3 Oct 2015
    2.1
    Low

    CVE-2015-1015

    Last Modified: 12 Apr 2025

    Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 use a reversible format for password storage in object files on Compact Flash cards, which makes it easier for local users to obtain sensitive information by reading a file.

    Published: 3 Oct 2015
    6.8
    Medium

    CVE-2015-5644

    Last Modified: 12 Apr 2025

    The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors.

    Published: 3 Oct 2015
    6.5
    Medium

    CVE-2015-5645

    Last Modified: 12 Apr 2025

    ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.

    Published: 3 Oct 2015
    7.8
    High

    CVE-2015-3938

    Last Modified: 12 Apr 2025

    The HTTP application on Mitsubishi Electric MELSEC FX3G PLC devices before April 2015 allows remote attackers to cause a denial of service (device outage) via a long parameter.

    Published: 3 Oct 2015
    6.5
    Medium

    CVE-2015-5640

    Last Modified: 12 Apr 2025

    baserCMS before 3.0.8 allows remote authenticated users to modify arbitrary user settings via a crafted request.

    Published: 3 Oct 2015
    6.5
    Medium

    CVE-2015-5641

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in baserCMS before 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 3 Oct 2015
    6.5
    Medium

    CVE-2015-5642

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 3 Oct 2015
    6.8
    Medium

    CVE-2015-5643

    Last Modified: 12 Apr 2025

    The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors.

    Published: 3 Oct 2015
    3.5
    Low

    CVE-2015-6549

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in an application console in the server in Symantec NetBackup OpsCenter before 7.7.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Oct 2015
    7
    High

    CVE-2015-0572

    Last Modified: 12 Apr 2025

    Multiple race conditions in drivers/char/adsprpc.c and drivers/char/adsprpc_compat.c in the ADSPRPC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service (zero-value write) or possibly have unspecified other impact via a COMPAT_FASTRPC_IOCTL_INVOKE_FD ioctl call.

    Published: 3 Oct 2015
    7.5
    High

    CVE-2015-5653

    Last Modified: 12 Apr 2025

    Buffer overflow in Canary Labs Trend Web Server before 9.5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet.

    Published: 2 Oct 2015
    4
    Medium

    CVE-2015-6308

    Last Modified: 12 Apr 2025

    Cisco NX-OS 6.0(2)U6(0.46) on N3K devices allows remote authenticated users to cause a denial of service (temporary SNMP outage) via an SNMP request for an OID that does not exist, aka Bug ID CSCuw36684.

    Published: 2 Oct 2015
    6.8
    Medium

    CVE-2015-6309

    Last Modified: 12 Apr 2025

    Cisco Email Security Appliance (ESA) 8.5.6-106 and 9.6.0-042 allows remote authenticated users to cause a denial of service (file-descriptor consumption and device reload) via crafted HTTP requests, aka Bug ID CSCuw32211.

    Published: 2 Oct 2015
    7.5
    High

    CVE-2015-2858

    Last Modified: 12 Apr 2025

    Datalex airline booking software before 2015-09-03 allows remote attackers to read or write to arbitrary user data via a modified profileId parameter to (1) ValidateFormAction.do or (2) ProfileConfirmEditAddressAction.do.

    Published: 2 Oct 2015
    9.3
    Critical

    CVE-2015-3876

    Last Modified: 12 Apr 2025

    libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file.

    Published: 2 Oct 2015
    7.8
    High

    CVE-2015-4546

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in EMC RSA OneStep 6.9 before build 559, as used in RSA Certificate Manager and RSA Registration Manager through 6.9 build 558 and other products, allows remote attackers to read arbitrary files via a crafted KCSOSC_ERROR_PAGE parameter.

    Published: 2 Oct 2015
    9.3
    Critical

    CVE-2015-6602

    Last Modified: 12 Apr 2025

    libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demonstrated by an attack against use of libutils by libstagefright in Android 5.x.

    Published: 2 Oct 2015
    7.2
    High

    CVE-2015-1335

    Last Modified: 12 Apr 2025

    lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.

    Published: 1 Oct 2015
    7.2
    High

    CVE-2015-1338

    Last Modified: 12 Apr 2025

    kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.

    Published: 1 Oct 2015
    6.8
    Medium

    CVE-2015-7612

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations page in Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.9 and earlier allow remote attackers to hijack the authentication of administrators for requests that have unspecified impact via unknown vectors.

    Published: 1 Oct 2015
    10
    Critical

    CVE-2014-7917

    Last Modified: 12 Apr 2025

    Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact and attack vectors, aka internal bug 15342615.

    Published: 1 Oct 2015
    10
    Critical

    CVE-2015-3832

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via invalid size values of NAL units in MP4 data, aka internal bug 19641538.

    Published: 1 Oct 2015
    9.3
    Critical

    CVE-2015-3858

    Last Modified: 12 Apr 2025

    The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypass an intended user-confirmation requirement for SMS short-code messaging via a crafted application, aka internal bug 22314646.

    Published: 1 Oct 2015
    10
    Critical

    CVE-2015-6575

    Last Modified: 12 Apr 2025

    SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly consider integer promotion, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via crafted atoms in MP4 data, aka internal bug 20139950, a different vulnerability than CVE-2015-1538. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7915, CVE-2014-7916, and/or CVE-2014-7917.

    Published: 1 Oct 2015
    6.8
    Medium

    CVE-2015-7674

    Last Modified: 12 Apr 2025

    Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf before 2.32.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted GIF image file, which triggers a heap-based buffer overflow.

    Published: 1 Oct 2015
    10
    Critical

    CVE-2014-7916

    Last Modified: 12 Apr 2025

    Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact and attack vectors, aka internal bug 15342751.

    Published: 1 Oct 2015
    10
    Critical

    CVE-2015-1538

    Last Modified: 12 Apr 2025

    Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496.

    Published: 1 Oct 2015
    9.3
    Critical

    CVE-2015-3831

    Last Modified: 12 Apr 2025

    Buffer overflow in the readAt function in BpMediaHTTPConnection in media/libmedia/IMediaHTTPConnection.cpp in the mediaserver service in Android before 5.1.1 LMY48I allows attackers to execute arbitrary code via a crafted application, aka internal bug 19400722.

    Published: 1 Oct 2015
    9.3
    Critical

    CVE-2015-3842

    Last Modified: 12 Apr 2025

    Multiple heap-based buffer overflows in libeffects in the Audio Policy Service in mediaserver in Android before 5.1.1 LMY48I allow attackers to execute arbitrary code via a crafted application, aka internal bug 21953516.

    Published: 1 Oct 2015
    7.2
    High

    CVE-2015-3860

    Last Modified: 12 Apr 2025

    packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters in the passwordEntry input field, which allows physically proximate attackers to bypass intended access restrictions via a long password that triggers a SystemUI crash, aka internal bug 22214934.

    Published: 1 Oct 2015
    6.8
    Medium

    CVE-2015-5286

    Last Modified: 12 Apr 2025

    OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.

    Published: 1 Oct 2015
    10
    Critical

    CVE-2014-7915

    Last Modified: 12 Apr 2025

    Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact and attack vectors, aka internal bug 15328708.

    Published: 1 Oct 2015
    9.3
    Critical

    CVE-2015-1528

    Last Modified: 12 Apr 2025

    Integer overflow in the native_handle_create function in libcutils/native_handle.c in Android before 5.1.1 LMY48M allows attackers to obtain a different application's privileges or cause a denial of service (Binder heap memory corruption) via a crafted application, aka internal bug 19334482.

    Published: 1 Oct 2015
    8.5
    High

    CVE-2015-1536

    Last Modified: 12 Apr 2025

    Integer overflow in the Bitmap_createFromParcel function in core/jni/android/graphics/Bitmap.cpp in Android before 5.1.1 LMY48I allows attackers to cause a denial of service (system_server crash) or obtain sensitive system_server memory-content information via a crafted application that leverages improper unmarshalling of bitmaps, aka internal bug 19666945.

    Published: 1 Oct 2015
    10
    Critical

    CVE-2015-1539

    Last Modified: 12 Apr 2025

    Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via crafted ESDS atoms, aka internal bug 20139950, a related issue to CVE-2015-4493.

    Published: 1 Oct 2015
    4.3
    Medium

    CVE-2015-1541

    Last Modified: 12 Apr 2025

    The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application that sends an Intent with a (1) FLAG_GRANT_READ_URI_PERMISSION or (2) FLAG_GRANT_WRITE_URI_PERMISSION flag, as demonstrated by bypassing intended restrictions on reading contacts, aka internal bug 19618745.

    Published: 1 Oct 2015
    10
    Critical

    CVE-2015-3824

    Last Modified: 12 Apr 2025

    The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly restrict size addition, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via a crafted MPEG-4 tx3g atom, aka internal bug 20923261.

    Published: 1 Oct 2015
    5
    Medium

    CVE-2015-3826

    Last Modified: 12 Apr 2025

    The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM), which allows remote attackers to cause a denial of service (integer underflow, buffer over-read, and mediaserver process crash) via crafted 3GPP metadata, aka internal bug 20923261, a related issue to CVE-2015-3828.

    Published: 1 Oct 2015
    9.3
    Critical

    CVE-2015-3827

    Last Modified: 12 Apr 2025

    The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not validate the relationship between chunk sizes and skip sizes, which allows remote attackers to execute arbitrary code or cause a denial of service (integer underflow and memory corruption) via crafted MPEG-4 covr atoms, aka internal bug 20923261.

    Published: 1 Oct 2015
    10
    Critical

    CVE-2015-3828

    Last Modified: 12 Apr 2025

    The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM), which allows remote attackers to execute arbitrary code or cause a denial of service (integer underflow and memory corruption) via crafted 3GPP metadata, aka internal bug 20923261, a related issue to CVE-2015-3826.

    Published: 1 Oct 2015
    10
    Critical

    CVE-2015-3829

    Last Modified: 12 Apr 2025

    Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via crafted MPEG-4 covr atoms with a size equal to SIZE_MAX, aka internal bug 20923261.

    Published: 1 Oct 2015
    4.3
    Medium

    CVE-2015-3833

    Last Modified: 12 Apr 2025

    The getRunningAppProcesses function in services/core/java/com/android/server/am/ActivityManagerService.java in Android before 5.1.1 LMY48I allows attackers to bypass intended getRecentTasks restrictions and discover the name of the foreground application via a crafted application, aka internal bug 20034603.

    Published: 1 Oct 2015
    10
    Critical

    CVE-2015-3834

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the BnHDCP::onTransact function in media/libmedia/IHDCP.cpp in libstagefright in Android before 5.1.1 LMY48I allow attackers to execute arbitrary code via a crafted application that uses HDCP encryption, leading to a heap-based buffer overflow, aka internal bug 20222489.

    Published: 1 Oct 2015
    9.3
    Critical

    CVE-2015-3835

    Last Modified: 12 Apr 2025

    Buffer overflow in the OMXNodeInstance::emptyBuffer function in omx/OMXNodeInstance.cpp in libstagefright in Android before 5.1.1 LMY48I allows attackers to execute arbitrary code via a crafted application, aka internal bug 20634516.

    Published: 1 Oct 2015